Uniqcli

CMMC control families

CMMC Incident Response (3.6 IR): 3 requirements and the 72-hour DIBNet clock

Three requirements — a capability, a reporting path and a test. Nobody sells you the plan or the rehearsal, and the part that actually catches contractors out is a registration they have not completed yet. What is quotable sits either side of it: the detection subscriptions that raise the alarm and the backup platform recovery depends on.

Family
3.6 — Incident Response
Requirements
3 of the 110 Level 2 requirements
Level 1
Not in Level 1 — appears at Level 2
Boundary
The capability behind the control — never a certification we hold
Overview

A capability, a reporting path, and proof you have exercised both

Incident response carries three requirements, 3.6.1 to 3.6.3: an operational incident-handling capability covering preparation, detection, analysis, containment, recovery and user response; tracking, documenting and reporting incidents to the designated officials inside and outside your organization; and testing that capability. Three requirements, and none of them is a product. What separates contractors who pass from contractors who do not is usually not tooling — it is whether the plan names people, whether those people have run it once, and whether the external reporting path was set up before it was needed. Tooling still has a place either side of the plan, and it is honest to name it: the detection and alerting subscriptions that tell you an incident is happening, and the backup platform and capacity the recovery step leans on. Both are quotable. Neither declares an incident, and neither writes the plan.

Levels

What each level asks of this family

A Level 1 self-assessment never asks whether you have a response plan. Incident response is a Level 2 family, outside the six that the 15 FAR 52.204-21 requirements touch — though the clock that actually catches contractors out, below, does not come from CMMC levels at all.

At Level 2 all three apply. Note the split between the standard and the contract clause: 3.6.2 is the NIST requirement to track, document and report incidents to designated internal and external officials, while the 72-hour clock most people mean when they say "CMMC reporting" comes from DFARS 252.204-7012, which requires a cyber incident affecting covered defense information to be reported to DoD within 72 hours of discovery through the DIBNet portal. Reporting through DIBNet needs a DoD-approved medium assurance certificate, and obtaining one takes long enough that doing it during an incident is not a plan.

Level 3 layers enhanced requirements from NIST SP 800-172 onto a Final Level 2, assessed by DIBCAC.

What's quotable

What you can actually quote around this family

Each card names the requirement the line serves — hardware, software licensing or the integration work that puts either into service. Naming a control is not a coverage claim: the configuration, the procedure and the evidence stay inside your program, and no purchase — hardware, license or service — confers certification on its own. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.

Limits

What no purchase closes here

There is no device that declares an incident, no appliance that writes a plan, and no purchase that evidences a tabletop exercise. Who declares, who reports, how quickly and to whom is your program, and 3.6.3's test is something people do rather than something you buy. A supplier quoting a box against 3.6 is quoting you something from another family with a different label on it.

One boundary worth stating twice: the confidentiality of backup CUI at rest is media protection's 3.8.9, not incident response. If the recovery half of your plan needs encrypted media or capacity, buy it against the requirement that actually governs it — the media protection page covers that.

We are not an assessor, a C3PAO or an RPO, and we hold no CMMC level. We quote against the SSP you already have — hardware, licensing and the integration work around them — not a generic bundle assembled around a level number.

Questions

Incident response questions

How long do you have to report a cyber incident to DoD?

Seventy-two hours from discovery, under DFARS 252.204-7012, for a cyber incident that affects covered defense information or the contractor's ability to perform operationally critical support. That clock comes from the contract clause, not from NIST SP 800-171 — 3.6.2 is the requirement to have a reporting process at all, to designated officials internal and external to your organization.

What is DIBNet and when do you have to use it?

DIBNet is the DoD portal defense contractors use to submit the cyber-incident report DFARS 252.204-7012 requires. Submitting through it requires a DoD-approved medium assurance certificate, which is an administrative process with a lead time — contractors who wait until an incident to start it are the ones who miss the 72-hour window. Starting that process before you need it, rather than during an incident, is the single easiest thing on this page.

How many incident response requirements are in NIST SP 800-171?

Three: 3.6.1 on an operational incident-handling capability, 3.6.2 on tracking, documenting and reporting incidents to designated officials, and 3.6.3 on testing that capability. Three of the 110 a Level 2 assessment covers.

Is incident response required at CMMC Level 1?

Not at Level 1. Incident response is one of the eight families that appear only at Level 2 and above. The DFARS 252.204-7012 reporting obligation is separate from CMMC levels entirely — if the clause is in your contract and you handle covered defense information, the 72-hour requirement applies regardless of what level a solicitation names.

Get a CMMC estimate — CMMC Incident Response (3.6 IR)

Tell us where to reach you and a Uniqcli specialist follows up by email to scope what you need across hardware, software licensing and integration, then comes back with pricing and availability — quoted against the SSP you already have, not a generic bundle.

An estimate for the capability behind the control — never a certification we hold. No purchase — hardware, license or service — confers a CMMC level on its own; what you buy makes the controls implementable.

Do not submit classified information, CUI, restricted FCI, export-controlled technical data, protected health information, payment-card data, passwords, or private keys through this form. Contact your Uniqcli representative or [email protected] to request an approved channel.

CUI, FCI and secure submission notice

Ask AI about Uniqcli

CMMC Incident Response (3.6 IR)

The plan is yours. The platform around it is a quote.

Incident response is a plan and a rehearsal, and we sell neither. Send the workload count, the retention target or the seat count and a Uniqcli specialist replies with an estimate for the backup and detection subscriptions and the capacity behind them — quoted against your term, with no claim that a license closes a requirement or that we handle the incident.